Skip to finding
important · Research — Agentic systems

A public Salesforce lead could make Agentforce exfiltrate CRM records and post trusted Slack phishing messages.

Affects

Salesforce Agentforce, a cloud AI-agent platform connected to CRM records and optionally deployed into Slack workspaces.

A stored prompt submitted through Web-to-Lead can run during routine review, query other CRM tables with the employee's permissions and move values through attacker-controlled DNS without a click.

Detail and 4 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 26, 2026